> Markdown version of [/jobs/ext/1248206-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/1248206-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** C2 Labs, Inc - **Location:** Knoxville, TN, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Continuous Integration, Github, Identity and Access Management, Python (Programming Language), Key Management, Log Analysis, Windows PowerShell, Runbook, Security Information and Event Management, Software Vulnerability Management, Data Logging, Information Technology, Bicep, RSA Archer Platform, Terraform, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f3eb4114a68a31a6 ## About the Role * 5+ years security engineering experience, including cloud security implementation and operations. * Hands-on experience with vulnerability management and secure configuration practices. * Working familiarity with cloud logging/monitoring, IAM guardrails, encryption/key management, and incident response readiness. * Comfort scripting/automation (PowerShell, Python, bash) and working with APIs/integrations. * Ability to communicate technical findings clearly to non-engineers and support audit/assessment discussions. Preferred / nice to have * Bachelor's degree in Computer Science, Engineering, IT, or related field * Azure security experience (Defender for Cloud, Sentinel/Log Analytics, Azure Policy, PIM) and/or Azure Government experience. * Experience supporting NIST 800-53 / FedRAMP assessments, remediation, or ConMon deliverables. * Security+ / AZ-500 / CISSP or similar certifications. * Experience integrating evidence into GRC platforms (RegScale preferred). Tools & environment * Cloud security tooling (customer-specific): vulnerability scanner, CSPM, SIEM/log pipeline, ticketing workflows * IaC and CI/CD tooling (Terraform/Bicep; GitHub Actions/Azure DevOps as applicable) * RegScale (linking technical evidence to controls/KSIs and ConMon cadence) Engagement details * 1099 independent contractor (initial engagement); project-based with potential extension into ConMon operations. * Remote-first; occasional on-site support only when customer environment requires it (rare). * No clearance required; must be able to pass a standard background check and sign NDA/SOW. ## Description C2 Labs is hiring a Security Engineer (Cloud Security Engineer) to support FedRAMP authorization acceleration and ongoing ConMon for defense-focused startups and companies deploying production workloads on Azure Government. You'll implement security controls, build repeatable evidence pipelines, and help make ConMon feel like an operational routine-not a monthly fire drill. What you'll do * Implement and tune cloud security controls (IAM, logging, vulnerability management, configuration baselines, incident readiness). * Configure security tooling and integrations to produce repeatable evidence for authorization and ConMon. * Support remediation and hardening workstreams, including vulnerability scan remediation support. * Help automate evidence exports / reporting inputs where feasible and keep operations sustainable post-authorization. Role summary Implement and operationalize technical security controls in customer cloud environments and build the telemetry/evidence pipelines that support FedRAMP 20X validation and ongoing ConMon. This role partners closely with the Cloud Architect and the technical writing team to ensure controls are not only implemented-but continuously evidenced. Key responsibilities * Implement and tune cloud security controls aligned to FedRAMP expectations (identity, logging, vulnerability management, configuration baselines, incident readiness). * Configure security tooling and integrations that generate repeatable evidence (e.g., vulnerability scanners, CSPM, SIEM/log aggregation, ticketing workflows). * Support vulnerability remediation and hardening activities (secure configurations, patching workflows, baseline images, configuration drift management). * Design and document evidence-producing processes and runbooks (what is collected, how, by whom, and on what cadence). * Support ongoing ConMon operations by producing/validating technical evidence inputs and assisting with POA&M remediation tracking. * Partner with writers to ensure technical narratives are accurate and match what is deployed; support assessor/sponsor technical Q&A as needed. * Where feasible, develop lightweight automation (scripts/APIs) to export evidence artifacts for GRC ingestion and reporting. Key deliverables / outputs * Configured security tooling and evidence outputs aligned to controls/KSIs. * Hardening/remediation recommendations and implementation support (with documented changes). * Runbooks and operational procedures for evidence generation and validation cadence. * Technical evidence inputs for ConMon cycles (e.g., scan outputs, logging configurations, control state reports)., * Work is typically in Azure Government environments supporting FedRAMP 20X and/or legacy packages. ## Related Videos - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)